About
J. Gregory McVerry, Ph.D., is a cybersecurity educator, instructional designer, and compliance strategist working at the intersection of learning science, national security, and the defense industrial base. He serves as Chief Information Officer of CyberDI and as an Associate Professor in Curriculum and Learning at Southern Connecticut State University.
At Southern Connecticut State University Greg studies disinformation and Nation-state building narratology. Greg applies principles of Open Pedagogy and learning as praxis for change. He prepares educators in teacher preparation. He teaches classes on New Literacies and Digital Technology for Lifelong learning, educational technology, emergent literacies, and Children’s Literature
At CyberDI, Greg leads the design of cybersecurity certification programs and professional learning for practitioners, consultants, assessors, executives, and defense contractors. He is the lead author of CyberAB-authorized Certified CMMC Professional and Certified CMMC Assessor courseware and has edited five books in the CyberDI CMMC Certification Series. He has helped develop CyberDI as a CyberAB Authorized Publishing Partner and Authorized Training Provider, an ISACA Accredited Training Organization, and a CMMC Level 2 certified organization.
Greg also works as a cybersecurity consultant with KNC Strategic Services, an authorized CMMC Third Party Assessment Organization. His consulting focuses on transforming regulatory requirements into cybersecurity programs that organizations can actually operate. He helps companies define their CUI boundaries, map data flows, categorize assets, develop System Security Plans, write policies and procedures, build role-based training, and assemble the evidence needed to demonstrate implementation of NIST SP 800-171.
Dr. McVerry is also a consultant with GL Solutions, INC specializing in 171 compliance for small government contractors who provide staffing services for a variety of government agencies in the DC area.
Much of his work supports small and midsized manufacturers navigating the difficult intersection of cybersecurity, business operations, federal contracting, export controls, and limited resources. He is especially interested in helping organizations distinguish genuine security requirements from unnecessary scope and expense. His approach begins with the contract and the data: determine what information must be protected, understand where it moves, establish a defensible boundary, and then build controls that fit how the organization actually works.
In 2026, Greg helped launch CyberDI’s CMMC Taiwan initiative and traveled to Taipei to teach CMMC to members of Taiwan’s defense supply chain. He developed courses for executives, cybersecurity professionals, and manufacturers supporting the semiconductor, aerospace, and unmanned-systems industries. This work extends his broader commitment to strengthening cybersecurity throughout the global supply chains on which the United States and its allies depend.
Greg earned his Ph.D. in Educational Psychology, with a concentration in Cognition, Instruction, and Learning Technologies, from the University of Connecticut. As a Neag Fellow in UConn’s New Literacies Research Lab, he studied how people read, learn, evaluate information, and build knowledge in digital environments. His academic work has produced dozens of scholarly papers, articles, chapters, books, presentations, and funded projects.
Before entering the CMMC ecosystem, Greg developed web-literacy curriculum for the Mozilla Foundation, leadership training for Mozilla, and principles of effective online instruction for the Association of College and University Educators. Mozilla recognized him as a member of its inaugural Network50—50 people whose work made the internet a better place. He also founded community programs that taught young people to code, evaluate online information, publish on the open web, and take ownership of their digital identities.
That background continues to shape his cybersecurity work. Greg does not view compliance as a checklist or cybersecurity as solely an IT responsibility. Organizations become secure when people understand what they must protect, why it matters, how their responsibilities fit together, and what evidence demonstrates that the work is being done.
He is also exploring how artificial intelligence can improve cybersecurity documentation, role-based training, assessment preparation, and continuous compliance. He treats AI as a tool for extending professional judgment—not replacing it—and emphasizes that every generated statement must remain accurate, operationally true, and supported by evidence.
Through Dr. Mac’s Cybersecurity Brief, Greg translates CMMC, NIST SP 800-171, federal contracting requirements, and cybersecurity governance into practical guidance. The goal is simple: help readers move beyond compliance theater and build cybersecurity programs that are understandable, affordable, defensible, and sustainable.